A vulnerability was found in WSO2 API Control Plane, API Manager, API Manager Publisher REST API V4, API Manager Traffic Manager, Carbon API Management API, Carbon API Management Implementation and Universal Gateway. It has been declared as problematic. Impacted is an unknown function of the component System REST API. Such manipulation leads to unrestricted upload.
This vulnerability is listed as CVE-2026-3418. The attack may be performed from remote. There is no available exploit.